MSSQL over the internet but we connect over RDP - Database Administrators Stack Exchangemost recent 30 from dba.stackexchange.com2019-09-15T13:31:21Zhttps://dba.stackexchange.com/feeds/question/242639https://creativecommons.org/licenses/by-sa/4.0/rdfhttps://dba.stackexchange.com/q/2426392MSSQL over the internet but we connect over RDPorcahttps://dba.stackexchange.com/users/1852642019-07-11T10:35:48Z2019-07-18T06:27:52Z
<p>We connect throguh RDP to our ERP solution which uses MSSQL 2008, right now I can see on windows logs and SQL logs that we have a HUGE amount of connection attempts to sa user and results in slow connections to us, users.</p>
<p>Since we connect through RDP and both ERP and DB are on the same server, I think I can close SQL port to the internet, and that would stop direct attacks to the DB, but our IT consultant it's not sure about it. I think it's safe to say that the only ports needed to be open through internet are RDP ports, besides that all happens in a LAN enviroment.</p>
<p>Am I right or am I missing something?</p>
https://dba.stackexchange.com/questions/242639/-/242745#2427455Answer by Max Vernon for MSSQL over the internet but we connect over RDPMax Vernonhttps://dba.stackexchange.com/users/108322019-07-12T12:18:23Z2019-07-12T12:18:23Z<p>I wrote a blog post about the perils of having your <a href="https://www.sqlserverscience.com/security/internet-access-to-your-sql-server/?utm_medium=referral&amp;utm_source=dba.stackexchange.com&amp;utm_campaign=242639" rel="noreferrer">SQL Server exposed to the internet</a>. </p>
<p>You should almost <em>never</em> allow internet access directly to SQL Server. From your description, it sounds like you have no requirement for that, since you RDP into the machine for access. I would immediately ensure the port used by the SQL Server is blocked at the firewall.</p>
https://dba.stackexchange.com/questions/242639/-/243154#2431540Answer by orca for MSSQL over the internet but we connect over RDPorcahttps://dba.stackexchange.com/users/1852642019-07-18T06:27:52Z2019-07-18T06:27:52Z<p>Finally found the problem to those recurent connections and the issue had nothing to do with MSSQL being exposed to the inernet, because it was never opened to it in the first place. It turned out that there was another service in the VM that used the same port as our ERP license server hence launching a lot of failed connection attempts. Once this other service was stopped and changed the port, everything returned to normal.</p>
<p>In order to find this, <code>netstat -abno</code> command provided really useful, and it's the tool that gave us the solution to stop those 4 connections every second.</p>
<p>Thanks everyone for the help and insight.</p>